Report vulnerabilities privately through GitHub Security Advisories for axioval/engine. Do not open a public issue containing an exploit, malicious ruleset, or sensitive project data.
Rule packages are untrusted data. The engine never executes package-provided code; applications must register trusted capability implementations explicitly.